VYPR

CWE-311

Missing Encryption of Sensitive Data

ClassDraftLikelihood: High

Description

The product does not encrypt sensitive or critical information before storage or transmission.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-157 · CAPEC-158 · CAPEC-204 · CAPEC-31 · CAPEC-37 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-477 · CAPEC-609 · CAPEC-65

CVEs mapped to this weakness (522)

page 24 of 27
  • CVE-2020-3389MedAug 26, 2020
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive information is stored…

  • CVE-2019-2231MedDec 6, 2019
    risk 0.29cvss 4.4epss 0.00

    In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9…

  • CVE-2018-1938MedMar 5, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153318.

  • CVE-2018-1937MedMar 5, 2019
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.

  • CVE-2025-64147MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-64146MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-64145MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-64144MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-64143MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2023-30523MedApr 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file…

  • CVE-2022-34307MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.01

    IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and…

  • CVE-2015-3207MedJul 7, 2022
    risk 0.28cvss 5.3epss 0.01

    In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

  • CVE-2021-38977MedNov 15, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The…

  • CVE-2021-29883MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site…

  • CVE-2019-4704MedJul 1, 2020
    risk 0.28cvss 4.3epss 0.01

    IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie…

  • CVE-2017-8168MedNov 22, 2017
    risk 0.28cvss 4.3epss 0.00

    FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not encrypted. An attacker accessing the internal network may…

  • CVE-2026-53442MedJun 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read…

  • CVE-2023-33837MedOct 23, 2023
    risk 0.27cvss 4.1epss 0.00

    IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.

  • CVE-2023-43618MedSep 20, 2023
    risk 0.27cvss 5.3epss 0.00

    An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.

  • CVE-2022-3250MedSep 21, 2022
    risk 0.27cvss 5.3epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.